Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)

⚠ Common exam trap

CAS-005 often tests the ability to distinguish DNS tunneling indicators from other attack indicators, causing candidates to select generic exfiltration signs like HTTP traffic or failed logins instead of DNS-specific anomalies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Large DNS response packets (greater than 512 bytes)

Option B is correct because DNS tunneling typically requires encoding data in DNS responses, which pushes packet sizes beyond the standard 512-byte UDP DNS limit and often forces TCP fallback or EDNS0 usage, making large DNS response packets a strong indicator. Option D is correct because tunneling tools encode exfiltrated data into subdomain labels, producing long, high-entropy, randomly generated subdomains that are atypical of legitimate DNS traffic. Option E is correct because DNS tunneling generates a high volume of queries from a single host as data is chunked and sent in many small DNS requests, so an unusual spike in query count from one internal host supports the hypothesis. Option A does not belong because failed login attempts indicate authentication attacks such as brute forcing, not DNS-based exfiltration. Option C does not belong because unencrypted HTTP to external IPs is a general web traffic observation and is not specific to DNS tunneling, which operates over port 53.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A sudden increase in failed login attempts

    Why it's wrong here

    Failed logins indicate authentication brute-forcing or credential attacks, not DNS tunnelling, which hides data inside DNS queries and responses. It is tempting because authentication failures are a common SIEM indicator, and would be the correct choice when investigating password spraying or account lockout activity rather than covert exfiltration.

  • ✓

    Large DNS response packets (greater than 512 bytes)

    Why this is correct

    DNS tunnelling encodes exfiltrated data into DNS records, inflating responses well beyond the 512-byte UDP limit and often forcing TCP fallback. Large response packets therefore satisfy the stem's requirement for network indicators supporting the DNS tunnelling hypothesis.

  • ✗

    Unencrypted HTTP traffic to external IPs

    Why it's wrong here

    DNS tunnelling hides exfiltration inside DNS queries and responses, so plaintext HTTP to external IPs indicates a different channel. It is tempting because unencrypted traffic exposes payloads, but that suits HTTP-based exfiltration. DNS tunnelling instead shows anomalous query volume, long encoded subdomains and TXT-record abuse.

  • ✓

    DNS queries for domains with long subdomains and random characters

    Why this is correct

    Tunnelling tools encode data into the query name itself, producing long, high-entropy subdomains that carry payload chunks to an attacker-controlled authoritative server. This satisfies the stem's requirement for a network indicator consistent with DNS-based exfiltration.

  • ✓

    An unusually high number of DNS queries from a single host

    Why this is correct

    Tunnelling generates far more DNS requests than normal host behaviour, as each chunk of exfiltrated data requires its own query. A single host issuing an unusually high volume of DNS queries satisfies the stem's requirement for an indicator supporting the DNS tunnelling hypothesis.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.